
Firmware security analysis of BD Alaris 8015 infusion pump (CVE-2016-9355). Identified 6 compound vulnerabilities including plaintext Wi-Fi credentials, HTTP firmware updates, and disabled integrity checks. STRIDE threat modeling and MITRE Playbook validation.
Firmware Security Analysis of the BD Alaris 8015 PC Unit: Unencrypted Wi-Fi Credential Storage and Compound Vulnerabilities (CVE-2016-9355)
This project presents a firmware security analysis of the BD Alaris 8015 Point-of-Care (PC) infusion pump, focusing on CVE-2016-9355 — a vulnerability that allows extraction of unencrypted Wi-Fi credentials from the device's NAND flash memory.
Course: CY 7790 - Medical Device Cybersecurity
Professor: Kevin Fu (Former Acting Director, Medical Device Cybersecurity at FDA)
Institution: Northeastern University
Team: Kalyan, Varun, Abisath, Arafat
The device stores wireless network credentials in plaintext XML files on NAND flash, including:
| Vulnerability | Severity | Description |
|---|---|---|
| HTTP Firmware Updates | High | Update channel uses unencrypted HTTP with MD5-only integrity |
| Disabled CRC Verification | High | OSE.ELF (main app) boots without integrity check (CRC=0xFFFFFFFF) |
| ProFTPD 1.3.3g (3 CVEs) | Medium | CVE-2011-4130, CVE-2010-4221, CVE-2010-3867 |
| Unauthenticated PPP | Medium | PPP configured without PAP/CHAP authentication |
| ValidateServerCert=false | Medium | PEAP profiles vulnerable to evil-twin RADIUS attacks |
| DNS Hijack Vector | Medium | Unqualified hostname 'natasha' enables firmware redirect |
| Component | Details |
|---|---|
| Processor | Atmel AT91SAM9G20 (ARM926EJ-S @ 400MHz) |
| Memory | 32 MB SDRAM, 64 MB NAND Flash |
| Wi-Fi Module | Laird WB40N (Broadcom BCM4329) |
| RTOS | ENEA OSE 4.5.2/4.6.1 |
| Main Binary | OSE.ELF (7.86 MB ARM ELF) |
/etc/summit/[ProfileName].xml
/PSK/Passphrase/text() /Password/text() /PEAP/Identity/text() /EAPTLS/PrivateKeyPassphrase/text() /EAPTLS/UserCertPassphrase/text() /AES/Key/text()
| Category | Threat | Impact |
|---|---|---|
| Spoofing | Stolen Wi-Fi PSK used to join hospital network | Network compromise |
| Tampering | HTTP firmware channel allows malicious updates | Device compromise |
| Repudiation | Disabled CRC leaves no audit trail | Undetectable tampering |
| Info Disclosure | CVE-2016-9355 plaintext credential extraction | Credential theft |
| Denial of Service | ProFTPD stack overflow (CVE-2010-4221) | Service crash |
| Elevation of Privilege | Domain credentials enable lateral movement | Hospital-wide breach |
| Threat | Mitigation | Status |
|---|---|---|
| Plaintext credentials | AES encryption with hardware-bound key (HKDF from GUID) | Fixed in v9.5+ |
| HTTP firmware updates | HTTPS + RSA/ECDSA code signing | Not addressed |
| MD5 integrity | SHA-256 + signed manifest | Not addressed |
| Disabled OSE.ELF CRC | SHA-256 verification at boot | Not addressed |
| ProFTPD vulnerabilities | Update to 1.3.8 or disable service | Not addressed |
This research was conducted for academic purposes under the Medical Device Cybersecurity course at Northeastern University. All analysis was performed on firmware images only — no physical devices were accessed. Credential samples shown are fictional and for demonstration purposes only.
Author: Mohammed Arafat Nadaf
GitHub: github.com/nadafarafat
LinkedIn: linkedin.com/in/arafatnadaf